CVE-2015-7267
Severity CVSS v4.0:
Pending analysis
Type:
CWE-254
Security Features
Publication date:
27/11/2017
Last modified:
20/04/2025
Description
Samsung 850 Pro and PM851 solid-state drives and Seagate ST500LT015 and ST500LT025 hard disk drives, when in sleep mode and operating in Opal or eDrive mode on Lenovo ThinkPad T440s laptops with BIOS 2.32; ThinkPad W541 laptops with BIOS 2.21; Dell Latitude E6410 laptops with BIOS A16; or Latitude E6430 laptops with BIOS A16, allow physically proximate attackers to bypass self-encrypting drive (SED) protection by leveraging failure to detect when SATA drives are unplugged in Sleep Mode, aka a "Hot Plug attack."
Impact
Base Score 3.x
4.20
Severity 3.x
MEDIUM
Base Score 2.0
1.90
Severity 2.0
LOW
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:samsung:850_pro_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:samsung:850_pro:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:samsung:pm851_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:samsung:pm851:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:seagate:st500lt015_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:seagate:st500lt015:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:seagate:st500lt025_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:seagate:st500lt025:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://www.blackhat.com/docs/eu-15/materials/eu-15-Boteanu-Bypassing-Self-Encrypting-Drives-SED-In-Enterprise-Environments-wp.pdf
- https://www.infoworld.com/article/3004913/encryption/self-encrypting-drives-are-hardly-any-better-than-software-based-encryption.html
- https://www.blackhat.com/docs/eu-15/materials/eu-15-Boteanu-Bypassing-Self-Encrypting-Drives-SED-In-Enterprise-Environments-wp.pdf
- https://www.infoworld.com/article/3004913/encryption/self-encrypting-drives-are-hardly-any-better-than-software-based-encryption.html



